Skip to main content

Help us improve the Digital Marketplace - send your feedback

Humble

Humble Education

Humble Education allows schools to plan, monitor and evaluate their extra curricular provision/enrichment activities. By connecting to your MIS, individual student progress can be tracked and linked to academic performance, in addition to being able gain insights on the school as a whole through the use of powerful reporting features.

Features

  • Integration with MIS
  • Real-time reporting
  • Works with existing hardware
  • QR code based sign in system
  • Parent/guardian and student portal
  • Report builder
  • Automated data integrity checks
  • Ability to process payments
  • Role based access control and permissions
  • Accident/incident logging

Benefits

  • Allow stakeholders to directly access the reports they require
  • Automatically keep parents/guardians up to date
  • Create reports that contain exactly the information you need
  • Automate registration process
  • Eliminate double bookings and registration errors
  • Improve communication between staff and students efficiently
  • Make data-driven decisions
  • Easily see the impact of enrichment on academic performance
  • Make safeguarding easier and more comprehensive
  • Improve efficiency from day one, without investing in new hardware

Pricing

Service documents

Request an accessible format
If you use assistive technology (such as a screen reader) and need versions of these documents in a more accessible format, email the supplier at tenders@wearehumble.co.uk. Tell them what format you need. It will help if you say what assistive technology you use.

Framework

G-Cloud 15

Service ID

5 4 9 9 6 7 3 5 5 4 4 7 6 7 3

Contact

Humble Andy Green
Telephone: 0330 229 5066
Email: tenders@wearehumble.co.uk

About your service

Service categories

Applications

Production and operations

  • Other operations
Multi cloud support
No

Service scope

Software add-on or extension
No
Cloud deployment model
Public cloud
Service constraints
Humble Education is only available as a hosted solution (not on-premise/self hosted).
System requirements
  • An active internet connection
  • Users must be able to use MFA

User support

Email or online ticketing support
Yes
Support response times
We aim to respond to all support requests within 24 - 48 hours, but it is often within a couple of hours during office hours (9 AM to 5 PM - Monday to Friday). Outside of office hours, we still aim to respond within 24 - 48 hours. For urgent requests, we typically respond within the hour and move to telephone support.
User can manage status and priority of support tickets
No
Phone support
Yes
Phone support availability
9 to 5 (UK time), Monday to Friday
Web chat support
No
Onsite support
Yes, at extra cost
Support levels
Basic support, provided to all customers, is primarily support ticket based. We reply fastest within our office hours but support tickets are monitored outside of office hours. Tickets can be escalated by our team, at which point we may decide that it is more efficient to use a different means of communication or plan a site visit.
We can also offer Service Level Agreements (SLAs) on a bespoke basis. These can include guaranteed response times, dedicated account managers, priority support and regular meetings/visits. They are priced according to an organisation's requirements.
Support available to third parties
Yes

Onboarding and offboarding

Getting started
When a school first signs up to the service, we reach out to them in order to connect their MIS to Humble Education and provide a walkthrough of the service. We have built help text and prompts within the service itself but we also recommend training for anyone who will be using it. This is delivered by us at any time and can be done remotely or onsite, according to the preference of the customer.
Service documentation
No
End-of-contract data extraction
Any report, as well as lists of information, can be exported from the system in various formats (most commonly CSV and Excel workbooks) at any time via the interface. We can also create custom data extracts for users upon request.
End-of-contract process
At the end of the contract, customers retain full access to their account for 30 days to export data, which we are happy to assist with. Customer data is retained for 30 days after contract termination to allow for reactivation, after which it is securely and permanently deleted in accordance with UK GDPR requirements. Final invoices are issued and any outstanding payments settled. No charges apply for data export, but we may charge if customers require support migrating to another service.

Using the service

Web browser interface
Yes
Supported browsers
  • Microsoft Edge
  • Firefox
  • Chrome
  • Safari
  • Opera
  • Other
Application to install
No
Designed for use on mobile devices
Yes
Differences between the mobile and desktop service
For the most part, it is possible to do everything that you can on a desktop on a mobile device. However, when using a mobile device, it is not as easy to use some of the more advanced features such as reporting. On the other hand, the registration interface has been optimised for mobile devices.
Service interface
No
User support accessibility
EN 301 549
API
No
Customisation available
Yes
Description of customisation
Users with administrator access to the service can customise the colours used and upload their own logos via the Settings. These customisations affect emails sent, as well as the interface that students and parents/guardians use to book onto activities, monitor their attendance and make payments.

Scaling

Independence of resources
Humble Education operates on a multi-tenant architecture with strict data isolation between organisations. Each tenant's data is logically separated at the database level, preventing any cross-contamination. Our AWS infrastructure automatically scales resources based on demand, ensuring consistent performance across all customers. We implement rate limiting, asynchronous message processing for resource-intensive operations, and caching to prevent any single tenant from monopolising system resources. Performance is continuously monitored, and we maintain capacity headroom to handle usage spikes without impacting other users' experience.

Analytics

Service usage metrics
Yes
Metrics types
User activity (such as login date/time), usage per school and subject area, number of reports generated, logs on when attendance data is uploaded and the discrepancy between when data is uploaded vs when an activity actually took place, revenue collected. Many of these metrics can also be compared to previous periods.
Reporting types
  • Real-time dashboards
  • Reports on request
Resource tagging
Yes
FOCUS resource tagging
No

Resellers

Supplier type
Not a reseller

Staff security

Staff security clearance
Conforms to BS7858:2019
Government security clearance
Baseline Personnel Security Standard (BPSS)

Asset protection

Knowledge of data storage and processing locations
Yes
Data storage and processing locations
United Kingdom
User control over data storage and processing locations
No
Datacentre security standards
Managed by a third party
Penetration testing frequency
Less than once a year
Penetration testing approach
Another external penetration testing organisation
Protecting data at rest
  • Encryption of all physical media
  • Scale, obfuscating techniques, or data storage sharding
Data sanitisation process
Yes
Equipment disposal approach
A third-party destruction service
Data sanitisation type
  • Deleted data can’t be directly accessed / Cryptographic Erasure
  • Data Erasure

Data importing and exporting

Data export approach
Users export data through the same web interface they use on a day to day basis.
Data export formats
  • CSV
  • Other
Other data export formats
  • PDF
  • XLSX
  • JSON
Data import formats
CSV

Data-in-transit protection

Data protection between buyer and supplier networks
TLS (version 1.2 or above)
Data protection within supplier network
  • TLS (version 1.2 or above)
  • IPsec or TLS VPN gateway

Availability and resilience

Guaranteed availability
Humble Education is hosted on AWS infrastructure with auto-scaling capabilities to ensure high availability. While our standard service does not include a formal SLA, we maintain platform availability through redundant systems, automated monitoring, and proactive maintenance scheduling.
For customers requiring guaranteed uptime commitments, we offer bespoke Service Level Agreements providing up to 99% availability guarantees. These custom SLAs include:
Availability Commitment: Up to 99% monthly uptime (excluding scheduled maintenance windows notified 7 days in advance)
Service Credits: If guaranteed availability is not met, customers receive percentage-based refunds of their monthly SLA fee, calculated proportionally to the shortfall in uptime
Monitoring & Reporting: Automated uptime tracking with monthly availability reports provided to SLA customers
Exclusions: Downtime caused by Force Majeure events, customer-initiated actions, or emergency security patches are excluded from SLA calculations.
Customers interested in formal availability commitments should contact us to discuss bespoke SLA requirements tailored to their specific needs and risk profile.
Approach to resilience
Humble Education is built on AWS infrastructure designed for high availability and resilience:
Infrastructure Redundancy: We use auto-scaling across multiple availability zones, ensuring service continuity if individual servers or zones experience issues. Load balancers automatically distribute traffic and route around failed instances.
Database Resilience: Databases are automated daily backups with point-in-time recovery capability. Database instances can be configured with Multi-AZ deployment for automatic failover, maintaining data availability during infrastructure failures.
Scalability: Auto-scaling groups automatically adjust capacity based on demand, preventing performance degradation during traffic spikes while maintaining cost efficiency during low-usage periods.
Monitoring & Response: Automated monitoring with CloudWatch alerts enables rapid detection and response to system issues. Performance metrics, error rates, and availability are continuously tracked.
Disaster Recovery: Automated daily backups retained for 30 days enable rapid recovery from data corruption or system failures. Recovery Time Objective (RTO) and Recovery Point Objective (RPO) targets can be defined in bespoke SLAs.
Security Updates: Critical security patches are applied promptly, with routine updates scheduled during low-usage periods with advance customer notification.
Detailed resilience documentation including architectural diagrams and incident response procedures is available on request.
Outage reporting
Customers will be alerted to any outages, and updates related to them, via emails to sent to all administrators within their account. Over time, we will also be introducing a public dashboard that serves as a log for any incidents.

Identity and authentication

User authentication needed
Yes
User authentication
  • Multi-Factor Authentication (MFA)
  • Public key authentication (including by TLS client certificate)
  • Identity federation with existing provider (for example Google Apps)
  • Username or password
Access restrictions in management interfaces and support channels
We strictly control access through role-based access control (RBAC) and multi-factor authentication (MFA) and continually review the roles that each member of staff has.
Version control systems (BitBucket) require two-factor authentication and access is granted only to development team members. Deployment pipeline access is controlled through AWS IAM roles with granular permissions.
Customer support channels (email helpdesk) authenticate users through verified email addresses and account details verification. Sensitive account modifications require additional validation steps.
All administrative access is logged and monitored via AWS CloudTrail, creating comprehensive audit trails for security review and compliance purposes.
Access restriction testing frequency
At least every 6 months
Management access authentication
  • Multi-Factor Authentication (MFA)
  • Public key authentication (including by TLS client certificate)
  • Identity federation with existing provider (for example Google Apps)
  • Username or password

Audit information for users

Access to user activity audit information
Users have access to real-time audit information
How long user audit data is stored for
User-defined
Access to supplier activity audit information
Users have access to real-time audit information
How long supplier audit data is stored for
User-defined
How long system logs are stored for
At least 12 months

Security governance

Named board-level person responsible for service security
Yes
Security governance certified
Yes
Security governance standards
Other
Other security governance standards
Cyber Essentials & Cyber Essentials Plus
Information security policies and processes
Humble maintains comprehensive information security policies with clear accountability and oversight structures. Our security framework includes:
Data Protection: Full UK GDPR compliance with documented privacy policies, data processing agreements, and regular reviews of data handling practices.
Access Controls: Role-based access within the application, multi-factor authentication for administrative access, password hashing using bcrypt, and principle of least privilege across all systems.
Infrastructure Security: AWS-managed infrastructure with encryption at rest (RDS) and in transit (TLS 1.2+), automated security patching, isolated multi-tenant architecture, and continuous monitoring.
Development Practices: Secure coding standards, regular dependency updates, input validation and sanitization, and thorough testing before deployment.
Incident Response: Documented procedures for security incidents including customer notification protocols and breach reporting to ICO where required.
Compliance: Cyber Essentials Plus certified, with regular security reviews and annual policy updates. Our AWS infrastructure benefits from their compliance certifications (SOC 2, ISO 27001).
All security policies are documented, regularly reviewed, and enforced throughout the development and operational lifecycle. Reporting structures ensure accountability and rapid response to security concerns, with developers currently reporting to company directors.
Software Security Code of Practice
Yes

Operational security

Configuration and change management standard
Supplier-defined controls
Configuration and change management approach
All code and infrastructure components are version-controlled in Git (BitBucket) using GitFlow branching strategy, maintaining complete change history and traceability throughout the component lifecycle.
Changes follow a structured workflow: development occurs in feature branches, undergoes peer review via pull requests, and requires director/manager approval before merging to production branches. AWS CodePipeline automates deployment from approved branches, ensuring consistency and traceability.
Security impact assessment is integrated into the review process, evaluating changes for potential vulnerabilities, data exposure risks, authentication/authorization impacts, and dependency updates. Critical security changes receive enhanced scrutiny before deployment.
Vulnerability management type
Supplier-defined controls
Vulnerability management approach
Potential threats are continuously assessed through automated dependency scanning, infrastructure security bulletins, framework advisories, and vulnerability alerts. Sentry provides real-time error tracking to detect application anomalies indicating potential security issues.
Critical security patches are deployed within 24-48 hours following expedited testing. Routine updates are applied during scheduled maintenance windows. Cloud-managed services receive automatic security patches.
Threat intelligence sources include AWS Security Hub, framework-specific resources, OWASP, and NCSC alerts. CloudWatch and Sentry monitoring detect suspicious activity or exploitation attempts in real-time.
Protective monitoring type
Supplier-defined controls
Protective monitoring approach
Potential compromises are identified through monitoring AWS logs for suspicious activity patterns and Sentry for application errors and anomalies. Automated alerts also flag authentication failures, unusual access patterns, or resource consumption spikes.
Upon detecting potential compromises, we immediately investigate and assess severity/scope. Critical incidents trigger immediate containment actions including isolating affected systems, revoking compromised credentials, and blocking malicious traffic. Affected customers are notified within 72 hours.
Response times: Critical security incidents receive immediate attention (within 1 hour), high-priority issues within 4 hours, and standard incidents within 24 hours. All incidents are documented with root cause analysis and remediation steps
Incident management type
Supplier-defined controls
Incident management approach
In order to report an incident, we ask users to email as much detail as possible to an email address provided to them during the onboarding process. All incidents will first be reviewed by management, who will decide the best course of action and who should be responsible for resolving the issue. We do not currently have pre-defined processes as this ensures incidents are reviewed on a case by case basis. Once an incident is resolved, a manager will email a report to affected users outlining the incident and steps taken.
Post-quantum cryptography secure
No

Secure development

Approach to secure software development best practice
Supplier-defined process

Public sector networks

Connection to public sector networks
No

Pricing

Discount for educational organisations
Yes
Free trial available
Yes
Description of free trial
We offer an unlimited free trial for one school for 30 days - no payment required. During the trial, there is unrestricted access to the service and all features.
Link to free trial
https://education.wearehumble.co.uk/signup

Discount percentage by annual call-off contract value (excluding VAT)

Less than £250,000
0%
Between £250,000 and £500,000
0%
Between £500,001 and £1,000,000
0%
Between £1,000,001 and £2,500,000
0%
Between £2,500,001 and £5,000,000
0%
Over £5,000,001
0%

Non-mandatory Standards and certifications

ISO/IEC 27001 certification
No
ISO 28000:2022 certification
No
ISO 9001 certification
No
Quality management systems (QMS)
No
CSA STAR certification
No
PCI certification
No
Cyber essentials
Yes
Please provide your Cyber Essentials Certificate Number
Fbe92e99-66ea-4fcb-9c8e-80c026be5ed6
Cyber essentials plus
Yes
Please provide your Cyber Essentials Plus Certificate Number
8d157d52-25a4-43bd-8f9b-f6174b8c3fc2
Other security certifications
No

Social value

Section B - Commitment for Future: Delivery
  • Mission: Kick start economic growth. To secure the highest sustained growth in the G7 - with good jobs and productivity growth in every part of the country making everyone, not just a few, better off.

    Policy Outcome 1: Fair work: That offers fair wages and good working conditions. Help people get a job, stay in work, and progress in their careers, with good employment opportunities across the country. Notes: Where there is a large proportion of labour costs in the contract, commercial teams should consider MAC in Outcome 1 as a priority

    • Employment contracts that reflect actual hours worked; steps taken to ensure employees understand their contracts and have the ability to review and adjust them if actual hours regularly exceed contracted hours
    • Payment of more than the National Minimum Wage or National Living Wage (as appropriate) to the contract workforce
    • Support for the contract workforce by providing career advice, and providing opportunities for staff working on the contract with in-work progression career development into known skills shortages or high growth areas
    • Volunteering opportunities for staff
    • Understanding of the modern slavery risks and issues affecting the market, industry, sector or country (of origin or of source) relevant to the contract, and the workforce in the supplier’s own organisation and those of its key subcontractors
    • How these flow down the supply chain and are monitored Illustrative examples include reporting, site visits, audits, etc.
  • Mission: Kick start economic growth. To secure the highest sustained growth in the G7 - with good jobs and productivity growth in every part of the country making everyone, not just a few, better off.

    Policy Outcome 3: Resilient, innovative and flexible supply chains: Support economic growth through enabling resilient businesses, opportunities for small businesses and voluntary, community and social enterprises

    • Understanding of local demographics, needs and opportunities for the co-design of the goods, services and works to be delivered under the contract
    • Methods for engaging with different parts of the community (including the education system and charities representing the community) and how communities come together to inform decisions, strategy and projects to leave a positive legacy for future generations
    • Plans for positive actions with community groups.
    • Measures for making facilities used in the delivery of the contract available for community groups, education or training
    • Measures to engage users and communities and build relationships to increase community integration build trust and influence how the contract is delivered
    • Support for community-led initiatives relevant to the contract. Illustrative examples: improving transport links; reducing loneliness; helping with English language proficiency; and facilitating social mixing among people with different backgrounds
  • Mission: Make Britain a clean energy superpower: To cut bills, create jobs and deliver security with cheaper, zero-carbon electricity by 2030, accelerating to net zero

    Policy Outcome 4: Sustainable procurement practices: Reducing carbon footprints, minimising waste, and promoting the use of clean energy and green technologies.

    • Understanding of opportunities for additional environmental benefits delivery in the performance of the contract, including working towards net zero carbon emissions and use of clean energy and green technologies
    • Collaborative ways of working with the supply chain to deliver additional environmental benefits in the performance of the contract, including working towards net zero carbon emissions and use of clean energy and green technologies
    • Activities to reconnect people with the environment and increase awareness of ways to protect and enhance it
  • Mission: Break down barriers to opportunity: By reforming our childcare and education systems, to make sure there is no class ceiling on the ambitions of young people in Britain

    Policy Outcome 6: Employment and training: For those who face barriers to employment

    • Understanding of employment and skills issues, and of the skills and employment shortages of high growth sectors relating to the contract
    • Creation of employment opportunities particularly for those who face barriers to employment, such as prison leavers, care leavers and/or who are located in deprived areas, and for people in industries with known skills shortages or in high growth sectors
    • Understanding of the issues affecting the representation of disabled people in the workforce in the market, industry or sector relevant to the contract, and in the supplier’s own organisation and those of its key sub-contractors
    • Inclusive and accessible recruitment practices, and retention-focused activities, including those provided in the Guide for line managers on recruiting, managing and developing people with a disability or health condition
    • Introducing transparency to pay and reward processes
    • Working conditions which promote an inclusive working environment and promote retention and progression
    • Understanding of the issues affecting inequality in employment, skills and pay in the market, industry or sector relevant to the contract, and in the supplier’s own organisation and those of its key sub-contractors. Measures to tackle inequality in employment, skills and pay in the contract workforce
  • Mission: Break down barriers to opportunity: By reforming our childcare and education systems, to make sure there is no class ceiling on the ambitions of young people in Britain

    Policy Outcome 7: Creating a pipeline of opportunities: For the contract workforce, reducing barriers to entry for under-represented groups.

    • Understanding of the issues affecting the development of new skills by target cohort
    • Understanding of the underlying factors affecting improvements to reduce barriers to entry and training schemes for the target cohort(s) related to the contract workforce
    • Content of the outreach activity is designed to suit the target cohort
  • Mission: Build an NHS fit for the future: That is there when people need it; with fewer lives lost to the biggest killers; in a fairer Britain, where everyone lives well for longer.

    Policy Outcome 8: Increasing productivity through physical and mental wellbeing: In the supply chain and communities in the relevant area.

    • Understanding of issues relating to health and wellbeing, including physical and mental health, in the contract workforce
    • Understanding barriers to access to health and social care services or employment opportunities e.g. digital inclusion
    • Inclusive and accessible recruitment practices, development practices and retention policies that support-focused activities including those provided in the Guide for line managers on recruiting, managing and developing which support people with a disability or health condition

Service documents

Request an accessible format
If you use assistive technology (such as a screen reader) and need versions of these documents in a more accessible format, email the supplier at tenders@wearehumble.co.uk. Tell them what format you need. It will help if you say what assistive technology you use.